ZeroHour

CVE-2022-26501

KEV ransomwaremass

Unauthenticated RCE in Veeam Backup & Replication 10.x and 11.x

CISA: Veeam Backup & Replication Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2022-26501 is a critical (CVSS 9.8) missing-authentication/incorrect-access-control flaw in Veeam Backup & Replication 10.x and 11.x that allows unauthenticated remote code execution; it is one of two related flaws (CVE-2022-26500 and CVE-2022-26501) fixed together by Veeam. An attacker who can reach the affected backup service over the network can trigger the flaw without any credentials or user interaction and gain code execution with full confidentiality, integrity, and availability impact on the backup server. This hands attackers control of the backup infrastructure itself, which is valuable for harvesting stored credentials, tampering with or destroying backups, and moving laterally ahead of ransomware detonation. Any organization running Veeam Backup & Replication 10.x or 11.x is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-12-13 with known ransomware use, and public reporting associates these flaws with Cuba ransomware gang activity.

What to do: Apply Veeam's updates per vendor instructions to all 10.x and 11.x deployments and verify the patched build is installed on every backup server. Restrict network access to Veeam backup infrastructure (including any internet-exposed or cloud-facing Veeam services) to trusted management networks, and hunt for exploitation indicators given the known ransomware use. Because exploitation is in the wild, treat patching of Veeam backup servers as urgent and high priority.

Affected
Veeam Backup & Replication10.x and 11.x
Estimated exposure
mass≈10^5–10^6 backup server deployments (Veeam reports roughly 500k+ customers and 10.x/11.x were the then-current versions) — Estimated from Veeam's vendor-reported customer base of several hundred thousand organizations, of which a large share run Backup & Replication as the flagship product on the affected 10.x/11.x releases; exact counts are not published, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

CISA Known Exploited Vulnerability
Affected
Veeam Backup & Replication
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
veeam
Products
veeam backup \& replication
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news